Search
Security · Digital forensics
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution. | mukul975/ | 34k | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 2 | Supply chain investigation, evidence recovery, and forensic analysis for GitHub repositories. | Tommy-yw/ | 546 | 3 repos | ~5k | Automated safety check: Pass | MIT | 4 mo ago |
| 3 | Provides malware analysis and network traffic techniques for CTF challenges. | ljagiello/ | 3.4k | — | ~2.1k | Automated safety check: Notes | MIT | 27 days ago |
| 4 | Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution. | mukul975/ | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 5 | Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison. | mukul975/ | 34k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 6 | A skill your agent uses when asked to investigate Conditional Access policy changes, sign-in failures related to CA policies (error codes 53000, 50074, 530032), or suspected policy… | SCStelz/ | 249 | — | ~3.8k | Automated safety check: Pass | MIT | 2 days ago |
| 7 | 7.Dfir Digital forensics and incident response - Windows event log analysis, PCAP forensics, filesystem artifact analysis, AD attack detection, and timeline correlation. | transilienceai/ | 563 | — | ~1.5k | Automated safety check: Pass | MIT | 2 mo ago |
| 8 | Status-first routing, bounded evidence collection, and safety guidance for issue-graph. | vercel-labs/ | 127 | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | 9 days ago |
| 9 | Guides authorized packet capture and analysis with TShark, Wireshark's command-line tool, for security investigations, malware detection and forensic examination of network traffic. | AgentSecOps/ | 220 | 1 repo | ~4.8k | Automated safety check: Notes | Unknown | 5 mo ago |
| 10 | Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping. | mukul975/ | 34k | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 11 | Captures an analyzable sample from a live system when the target leaves no file on disk, by finding abnormal executable memory and the execution context that reached it. | dslsdzc/ | 135 | — | ~2k | Automated safety check: Pass | Apache-2.0 | 5 days ago |
| 12 | Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic. | mukul975/ | 34k | — | ~2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 13 | A skill your agent uses for authorized digital forensics including memory dumps, disk timelines, PCAP investigation, artifact triage, and IR evidence preservation. | zhaoxuya520/ | 41k | 2 repos | ~389 | Automated safety check: Warn | MIT | 18 days ago |
| 14 | Reconstructs folder browsing history from Windows Shellbag registry data using SBECmd and Shellbags Explorer, even for folders that were later deleted. | mukul975/ | 34k | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 15 | Black box flight recorder for the server. An agent skill from bolivian-peru/os-moda. | bolivian-peru/ | 119 | — | ~624 | Automated safety check: Pass | Apache-2.0 | 3 mo ago |
| 16 | A skill your agent uses when responding to or forensically investigating an incident — triage acquisition (Velociraptor/KAPE), Volatility 3 memory forensics, Chainsaw/Hayabusa EVTX timelining… | hypnguyen1209/ | 388 | — | ~2.5k | Automated safety check: Pass | MIT | 13 days ago |
| 17 | Provides digital forensics and signal analysis techniques for CTF challenges. | ljagiello/ | 3.4k | — | ~9.2k | Automated safety check: Warn | MIT | 27 days ago |
| 18 | Diagnostics-only BGP troubleshooting patterns for neighbor state, route exchange, prefix policy, AS path inspection, and safe evidence collection. | affaan-m/ | 276k | 1 repo | ~1.4k | Automated safety check: Pass | MIT | yesterday |
| 19 | Analyze disk images, file systems, and memory captures for digital evidence recovery in forensic investigations and CTF challenges. | briiirussell/ | 413 | — | ~1.5k | Automated safety check: Notes | MIT | 4 mo ago |
| 20 | Judge product usability and evidence quality. An agent skill from aryaniyaps/lamina. | aryaniyaps/ | 116 | — | ~432 | Automated safety check: Pass | Apache-2.0 | 9 days ago |
| 21 | Build collaborative forensic incident timelines using Timesketch to ingest, normalize, and analyze multi-source event data (including Plaso output) for attack chain reconstruction and investigation… | mukul975/ | 34k | — | ~2.4k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 22 | SQL-powered forensic investigation and system interrogation using osquery to query operating systems as relational databases. | AgentSecOps/ | 220 | 1 repo | ~4.9k | Automated safety check: Notes | Unknown | 5 mo ago |
| 23 | Endpoint visibility, digital forensics, and incident response using Velociraptor Query Language (VQL) for evidence collection and threat hunting at scale. | AgentSecOps/ | 220 | 1 repo | ~3.1k | Automated safety check: Pass | Unknown | 5 mo ago |
| 24 | Performs digital forensics investigation on compromised endpoints including memory acquisition, disk imaging, artifact analysis, and timeline reconstruction. | mukul975/ | 34k | — | ~2k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 25 | Perform forensic analysis of network packet captures (PCAP/PCAPNG) using Wireshark, tshark, and tcpdump to reconstruct network communications, extract transferred files, identify malicious traffic… | mukul975/ | 34k | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 26 | Authorized digital forensics: memory dumps, disk timelines, PCAP investigation, artifact triage, and incident-response evidence preservation. | sickn33/ | 47k | 1 repo | ~495 | Automated safety check: Pass | MIT | yesterday |
| 27 | Perform comprehensive forensic analysis of raw (dd), E01, or AFF disk images with Autopsy and The Sleuth Kit, recovering deleted files, examining metadata and embedded artifacts, keyword searching… | mukul975/ | 34k | — | ~2.7k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 28 | Performs Linux memory acquisition using LiME (Linux Memory Extractor) kernel module and analysis with Volatility 3 framework. | mukul975/ | 34k | — | ~631 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 29 | Parse Microsoft Outlook PST and OST files using libpff and pst-utils to extract message content, headers, attachments, deleted items, and MAPI metadata, including recovery of items from the… | mukul975/ | 34k | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 30 | Parses the Windows Amcache.hve registry hive with Eric Zimmerman's AmcacheParser and Timeline Explorer to extract evidence of program execution, application installation, and driver loading… | mukul975/ | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 31 | Analyzes Windows Security, System, and Sysmon event logs in Splunk to detect authentication attacks, privilege escalation, persistence mechanisms, and lateral movement using SPL queries mapped to… | mukul975/ | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 32 | Parse Windows LNK shortcut files to extract target paths, MAC timestamps, volume serial numbers, and machine identifiers for forensic timeline reconstruction. | mukul975/ | 34k | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 33 | Extract and analyze Windows Registry hives with tools like RegRipper and Registry Explorer to uncover user activity, installed software, autostart/persistence entries, and evidence of system… | mukul975/ | 34k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 34 | Generate forensic super-timelines with Plaso's log2timeline.py, pinfo.py, psort.py, and psteal.py CLI tools (fusing file-system MACB, registry, EVTX, browser history, prefetch, LNK, and more), then… | mukul975/ | 34k | — | ~1.9k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 35 | Detects rootkit presence on compromised systems by identifying hidden processes, hooked system calls, modified kernel structures, and covert network connections using Volatility memory forensics… | mukul975/ | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 36 | Extracts cached credentials, password hashes, Kerberos tickets, and authentication tokens from Windows memory dumps using Volatility 3, Mimikatz, and pypykatz. | mukul975/ | 34k | — | ~3.4k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 37 | Collect and analyze cloud forensic evidence using AWS CLI, Azure CLI, or gcloud to snapshot volumes, capture instance metadata and security group configurations, and preserve cloud-native logs… | mukul975/ | 34k | — | ~3.4k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 38 | Investigate AWS account compromise by querying CloudTrail with boto3's LookupEvents or AWS Athena SQL over S3-delivered logs, filtering on suspicious user agents, source IPs, and event names to… | mukul975/ | 34k | — | ~845 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 39 | Uses AWS Athena to query CloudTrail, VPC Flow Logs, S3 access logs, and ALB logs for forensic investigation. | mukul975/ | 34k | — | ~3.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 40 | Conduct disk forensics investigations using forensic imaging, file system analysis, and timeline reconstruction, with tools such as FTK Imager, Autopsy, and The Sleuth Kit, for evidence acquisition… | mukul975/ | 34k | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 41 | Investigates insider threat incidents involving employees, contractors, or trusted partners who misuse authorized access to steal data, sabotage systems, or violate security policies, combining… | mukul975/ | 34k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 42 | Executes a structured ransomware incident response from detection through containment, forensic analysis, decryption assessment, recovery, and post-incident hardening, covering ransom negotiation… | mukul975/ | 34k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 43 | A skill your agent uses when a security incident has been detected or declared and needs classification, triage, escalation path determination, and forensic evidence collection. | alirezarezvani/ | 28k | — | ~3.8k | Automated safety check: Pass | MIT | 1 mo ago |
| 44 | Analyze memory dumps using Volatility3 plugins to detect injected code, rootkits, credential theft, and malware artifacts in Windows, Linux, and macOS memory images. | mukul975/ | 34k | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 45 | Performs comprehensive Windows forensic artifact analysis using Eric Zimmerman's open-source EZ Tools suite (KAPE, MFTECmd, PECmd, LECmd, JLECmd, Timeline Explorer) to parse registry hives, prefetch… | mukul975/ | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 46 | Analyze Linux, SteamOS, Steam Deck, Wine, or Proton game-security boundaries. | gmh5225/ | 3.6k | — | ~220 | Automated safety check: Pass | MIT | today |
| 47 | Analyzes RAM memory dumps from compromised systems using the Volatility framework to identify malicious processes, injected code, network connections, loaded modules, and extracted credentials. | mukul975/ | 34k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 48 | Use Scapy to craft, send, sniff, and dissect TCP/UDP/ICMP/DNS packets, analyze pcap files, implement SYN scans, and detect anomalous traffic such as fragmented or malformed packets. | mukul975/ | 34k | — | ~626 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |